DPDP Act, 2023 — your law
Built around the DPDP Act's core duties: consent-based processing, purpose limitation, the rights of the data principal (your patient), and clear safeguards against misuse — with data held inside India.
Arogyam.ai safeguards every record with bank-grade encryption, strict access controls, and full audit trails — built for India's DPDP Act, 2023, engineered to HIPAA Security Rule standards, and designed to be ABDM-ready.
Patient records are among the most sensitive data a clinic holds. Protecting them is not a feature you bolt on — it is how the whole system is built. Arogyam.ai approaches data protection through three lenses that matter for a modern Indian practice: the law that governs you, the global engineering standard we hold ourselves to, and the national health network you'll grow into.
Your governing law is the DPDP Act. For clinics operating in India, the Digital Personal Data Protection Act, 2023 sets the rules for how patient data is collected, used, and protected. HIPAA is the international benchmark. While HIPAA is a United States law, its Security Rule has become the world's reference standard for health-data safeguards — and we engineer Arogyam to meet it. ABDM is India's digital-health network. We keep records ABHA-ready and FHIR-compatible so your clinic is positioned to connect to the Ayushman Bharat Digital Mission.
How Arogyam.ai maps to the frameworks that protect your patients — and your practice.
Built around the DPDP Act's core duties: consent-based processing, purpose limitation, the rights of the data principal (your patient), and clear safeguards against misuse — with data held inside India.
Engineered to the HIPAA Security Rule's administrative, physical, and technical safeguards — the international gold standard for health-data security. A Business Associate Agreement (BAA) is available where applicable.
Records are kept structured, HL7 FHIR-compatible, and ABHA-ready, so your clinic is positioned to connect with India's ABDM digital-health network.
The concrete controls behind every record in Arogyam.ai. Scroll to walk through each layer of protection.
Talk to our team →Sensitive patient data is encrypted with AES-256 using envelope encryption managed by Google Cloud KMS, so records are unreadable even at the storage layer.
Every connection is secured with TLS 1.3, so patient data is protected as it travels between your browser and our servers.
Least-privilege access controls mean doctors, front-desk, billing, and lab staff see only the data their role needs — nothing more.
Access to patient records is logged. A tamper-evident audit trail records who viewed or changed what, and when.
Patient data is hosted on Google Cloud infrastructure within India, in ISO 27001-certified data centres.
Encrypted, automated backups and disaster-recovery processes keep your records safe and available if the unexpected happens.
Your patients' data is used only to run your clinic. It is never sold, rented, or shared with third parties for advertising.
Built on Google Cloud — physically secured, continuously monitored, and certified to ISO 27001 and SOC 2 standards.
Patient data is processed on a consent-first basis — consent is captured, recorded, and revocable — in line with the DPDP Act's consent and purpose-limitation principles.
The HIPAA Security Rule groups protections into three categories. Here's how Arogyam.ai addresses each.
Unique user logins and role-based access, AES-256 encryption at rest and TLS in transit, audit logging of record access, and integrity controls so data can't be silently altered.
Access is provisioned by role on a least-privilege basis, with internal processes for risk review, change management, and responding to security incidents.
Data lives in Google Cloud data centres within India, with 24/7 physical security, environmental controls, and ISO 27001 / SOC 2 certification.
Whether you need a BAA, a security overview for your team, or details on data residency — talk to us. We'll give you straight answers.